Tavita

Privacy Policy

Last updated: August 2, 2026

The short version: your health data is stored on your phone, not on our servers — the few features that need the internet send only what that feature needs, and backups go to your own iCloud or Google Drive, encrypted. Here's the full version, in plain English.

  • Your health data — profile, meals, supplements, logs — is stored on your phone in a local database. No account or login required.
  • AI features send only what they need to work — a meal photo to analyze it, your supplement names and daily rhythm to build your schedule — and none of it is stored on our servers.
  • Optional community features store only what you choose to share. Your health logs are never synced to a server.
  • No ads, no trackers, no selling your data.

What Tavita is

Tavita is a nutrition and calorie tracker that also helps you organize the timing of supplements and medicines you already take. It is made and operated by Tavita OPC ("we," "us"). It is not a medical device, and it does not diagnose, treat, or provide medical advice — see our Terms of Service for the full picture.

This policy explains what data Tavita collects, what stays on your phone, what occasionally leaves it (and why), and the choices you have. We wrote it to actually be read, so it's longer on plain explanation than on legal boilerplate.

Data stored on your device

Tavita doesn't require an account or a login. When you use the core app, your data lives in a local database and local storage on your phone — Tavita keeps no ongoing server-side copy of it. (Some features do send specific pieces of it out to work — the next section lists every one of them, including the optional encrypted backups and phone-to-phone transfer.) The data stored on your phone includes:

  • Your profile: name, age, sex, body metrics, weight goal, health goals, diet type and allergens, wake/sleep and meal times, alcohol/smoking/caffeine habits, exercise level, pregnancy status, medical conditions, and blood pressure, if you choose to enter them.
  • Your supplements, medicines, and the schedules you build for them.
  • Meal logs, nutrient totals, and hydration, caffeine, and alcohol logs.
  • Sleep, weight, blood pressure, and activity logs you enter or sync.
  • Wellness and menstrual tracking, if you use it.
  • Progress photos, streaks, and badges.

You can export this data (as JSON or PDF) or delete it entirely from inside the app at any time. If you delete the app itself, this data is deleted with it — Tavita holds no server-side copy of it to clean up. (If you've made encrypted backups to your own iCloud or Google Drive, those files live in your own cloud account and are yours to delete there — see the backups section below. If you've turned on the optional community features described below, a separate, smaller set of data does live on our servers and isn't removed just by deleting the app — see Account & Data Deletion for how to remove that.)

Tavita also supports an optional app lock: a PIN, or Face ID / fingerprint. Biometric data is handled entirely by your phone's operating system — Tavita never sees or stores it, and it never leaves your device.

Data that leaves your device

Tavita is built to be private by design, and most of what you enter never leaves your phone. But a few features genuinely need to talk to a server to work. Here is every one of them, what's sent, and why.

1. AI photo analysis

When you photograph a meal — or pick an existing photo from your gallery — or scan a supplement or medicine label, that photo (and related text, like the supplement name) is sent over an encrypted connection to Tavita's own proxy server, which forwards it to Anthropic's Claude API for analysis. The results come back to your device. Our proxy uses the photo only to produce that analysis and does not store it. It does keep a small log line for every AI request — the IP address the request came from, a random identifier your app install generates (not your name, account, or any health data), which model was used, and how many tokens it used — so we can rate-limit abuse and account for cost; that log never contains the photo or the text you sent, and is deleted after 7 days (see "How long we keep things" below). Anthropic processes the photo as our AI provider, under its own API terms. Tavita also uses Claude for text-only AI features, like reasoning about your schedule or generating a weekly insight — those requests contain the relevant schedule or log data, not your full profile, but for a schedule check that does include the names of the supplements and medicines being scheduled, along with any diagnosed conditions, age, pregnancy status, and smoking status you've entered, since timing calls (an empty-stomach dose, a split dose, a bedtime placement) can depend on them.

2. Voice meal logging

When you log a meal by voice, your phone's built-in speech recognition service converts your speech to text — Apple's on iOS, Google's on Android. Depending on your device and language, that service may process the audio on Apple's or Google's servers, under their own terms; Tavita itself never receives or stores the audio. The resulting transcript — your spoken description of what you ate or drank — is then sent to our AI provider, through the same proxy described above, to turn it into loggable items, and is not stored on our servers. Voice logging is for food and drink only: supplements and medicines are never logged by voice.

3. Public database lookups

When you look up a food, supplement, or drug, Tavita queries public reference databases — the NIH Dietary Supplement Label Database (DSLD), RxNorm, openFDA, USDA FoodData Central, and Open Food Facts. These queries contain only the food, supplement, or drug name (or a barcode) — never your identity, profile, or health data.

4. Interaction checking

Interaction checking between the supplements and medicines you track starts with Tavita's own interaction database, compiled from published expert-consensus research and US government health sources. It ships inside the app itself and is queried entirely on your device. When a potential interaction needs to be classified or explained — or when a pair isn't covered by any database — the names of the two products or ingredients involved are sent to our AI provider, through the same proxy described above, to produce that classification or explanation. These requests contain only the substance names — never your identity, profile, or health data.

5. Purchases

Subscriptions are billed by the Apple App Store or Google Play, not by Tavita — we never see your card details. Purchases are processed through RevenueCat, our subscription infrastructure provider, which receives your purchase receipt, entitlement status, and an anonymous app user ID. If you apply a creator or affiliate code, that code is attached to your subscriber record so the creator gets credit.

Tavita also keeps its own record of each purchase event — including which affiliate or creator code, if any, was attached to it — on our backend (Supabase), for accounting and to calculate and pay affiliate commissions; see "How long we keep things" below for retention. If you subscribed using a creator's code, that creator can see the purchase events attributed to their own code: the product, price, and timestamp, identified only by your anonymous app user ID — never your name, email, or any health data.

6. Optional community features

Friends, challenges, leaderboards, the activity feed, feature voting, and referrals are all opt-in. If you turn any of these on, a username you choose, a lightweight account ID, your friend connections, challenge and leaderboard entries, activity-feed posts, and feature votes are stored on Tavita's backend (Supabase). If you send us a feature suggestion or a bug report, the text you write plus that lightweight ID is stored on the same backend in a private queue that only our team reads — it is never shown to other users. Sending one doesn't require turning on community features or picking a username: it's stored against the same anonymous ID even if you never join the community, and it's removed when you delete that profile or your account, like the rest. You choose what to share here — your private health logs are never synced to this backend, opted in or not.

7. Push notifications

Your everyday reminders — supplement times, hydration nudges, quest and streak reminders, nutrient alerts — are local notifications, generated and scheduled entirely on your phone; no server is involved. If you've joined the optional community features and allowed notifications, Tavita also stores a push notification token — an anonymous device identifier issued by Apple or Google — on our backend (Supabase), tied to your community account. Our server uses it only to deliver community notifications: friend requests, challenge invites and results, and referral updates. Turning notifications off removes the token, and deleting your community account deletes it along with the rest of your community data.

To prevent abuse of community push notifications, Tavita also logs the IP address a push send request came from, for anti-abuse rate limiting. These IP logs are kept for up to 30 days and then deleted, and are deleted early if you delete your community account.

8. Backups & device transfer

Backups are optional and off by default. If you turn them on, Tavita encrypts a full copy of your data — profile, logs, supplements, photos — on your device, using a passphrase only you know, and saves it to your owniCloud (on iOS) or Google Drive (on Android) account. Tavita's servers never receive or store these backups, and we can't read them: the passphrase is never sent to us, and on Google Drive the app uses a restricted permission that only lets it see files it created itself. Those backup files belong to you — deleting the app doesn't delete them; you can remove them from your iCloud or Drive storage at any time.

Separately from Tavita's own backup feature, your phone's operating system runs its own backups, and those may include the app's local data — iCloud device backup on iOS, Auto Backup on Android. Those copies go to your own Apple or Google account under their terms, not to us: Tavita can't see or access them, and you manage them (or turn them off) in your phone's settings.

Moving to a new phone works differently: the app encrypts the same kind of full copy with a one-time random key, uploads only the encrypted file to a private area of our backend (Supabase), and puts the key inside the QR code shown on your screen — the key itself never touches our servers, so we cannot decrypt what's in transit. The transfer is claimable once, expires after 15 minutes, and the encrypted file is deleted from our servers as soon as your new phone downloads it (or the transfer expires or is cancelled). This brief encrypted relay is the only time any copy of your health data passes through Tavita's servers.

9. Health platform data (Apple Health / Health Connect)

If you connect Apple Health or Health Connect, see the dedicated section below — Health platform data — for exactly what that involves and the commitments we make around it.

Health platform data

Connecting Apple Health or Health Connect is optional and requires your explicit permission through your phone's own permission dialog. When connected, Tavita reads two things: sleep sessions and workout sessions (a workout carries its own calorie total). It uses them to show your sleep and activity in the app's Health section and to include them in the reports and data exports you generate. Tavita only reads from these platforms — it doesn't write anything back to them.

Health data obtained through HealthKit or Health Connect is stored on your device and used solely to provide Tavita's health features. It can leave the phone only in the two encrypted forms described in Backups & device transfer above — an optional backup to your own iCloud or Google Drive, and the transient hand-off file used to move to a new phone — one encrypted with your backup passphrase, the other with a one-time key, neither of which we ever receive. On iOS, data imported from Apple Health is excluded from Tavita's backup and transfer files entirely, and re-syncs from Apple Health on your new device. It is never used for advertising or marketing, never sold, and never shared with third parties or data brokers.

How long we keep things

Retention depends on the kind of data and where it lives:

  • On-device data (profile, meals, supplements, logs, photos) — kept until you delete it yourself or delete the app.
  • Community data (username, friends, activity-feed posts, challenge and leaderboard entries, referral codes, push token) — kept until you delete your community account; see Account & Data Deletion.
  • Purchase records, including affiliate attribution — kept for as long as required for tax and accounting purposes (typically up to 7 years), and are not removed by deleting your community account or the app.
  • IP logs from community push anti-abuse checks — kept for up to 30 days, then deleted, and removed early if you delete your community account.
  • AI request logs — each AI request through our proxy records the IP address it came from, a random per-install identifier, which model was used, and how many tokens it used, for rate limiting and cost accounting. These logs never contain the photo or text you sent, and are deleted after 7 days. Before deletion, the token counts are added to a monthly total kept per random install identifier — never the IP address, and never any content — and those monthly totals are kept for up to 13 months so we can understand our AI costs.
  • Moderation records (content reports) — kept after account deletion, for community safety and abuse prevention. Blocks are not: the blocks you set, and the ones set against you, are deleted along with your account.
  • Device-transfer relay — the encrypted file is claimable once, expires after 15 minutes, and is deleted from our servers as soon as your new phone downloads it (or the transfer expires or is cancelled).

What we never do

  • We don't sell your data, to anyone, ever.
  • We don't run ads or work with ad networks in the app.
  • We don't build advertising or marketing profiles from your health data.
  • We don't use analytics SDKs, ad trackers, or crash-reporting SDKs in the app.
  • This website doesn't use cookies, analytics, or trackers either — it's a static site.

Your privacy rights

Depending on where you live, privacy laws — including the EU/UK GDPR and California's CCPA/CPRA — give you rights over your personal information. We honor these rights for every Tavita user, not only where a law requires it. Because most of your data already lives only on your device, you can exercise nearly all of them yourself, right inside the app:

  • Access. Ask what we hold and request a copy by emailing support@tavita.app.
  • Correction. Edit your profile, logs, supplements, and schedules directly in the app at any time.
  • Deletion. Delete your on-device data from inside the app, or delete your community account and its data — see Account & Data Deletion for step-by-step instructions.
  • Data portability.Export your data as JSON or PDF from inside the app at any time — see "Data stored on your device" above.
  • Objection & restriction. Turn off optional features (community, Health Connect / Apple Health) at any time to stop future data flow for that feature, or email support@tavita.app to ask us to restrict how we use data we hold.
  • We do not sell or share your personal information— for money or otherwise — and never have; see "What we never do" above.
  • No discrimination. We will never deny you service, charge you differently, or degrade your experience for exercising any of these rights.

Some of our infrastructure providers (Anthropic, RevenueCat, Supabase, Vercel) are based in the United States, so data processed through those features may be transferred to and processed in the US.

Security

All network requests Tavita makes — to our proxy, to public databases, to Apple/Google, or to our backend — go over HTTPS. On-device data is protected by your phone's own storage security and, if you enable it, an app-level PIN or biometric lock (Face ID or fingerprint), which your operating system handles directly.

No method of transmission or storage is perfectly secure, but because the vast majority of your data never leaves your device in the first place, there's very little for a server-side breach to expose.

Children

Tavita is not directed at children under 13, and its health-tracking features are intended for adults. We do not knowingly collect personal information from children under 13; if we learn we have, we delete it.

If you're between 13 and 17, please use Tavita with a parent or guardian's guidance, particularly around health and medication information.

Changes to this policy

If we change what data we collect or how we use it, we'll update this page and change the "last updated" date above. For a material change, we'll do our best to flag it inside the app as well.

Contact

Tavita is operated by Tavita OPC, and Marquis Mendoza is the person responsible for how your data is handled. Questions about this policy or your data? Email support@tavita.appand we'll get back to you.

Data sources & attributions

Tavita relies on the following public databases, licensed data, and infrastructure providers:

  • NIH Dietary Supplement Label Database (DSLD) — supplement label data, maintained by the National Institutes of Health. DSLD covers products sold in the United States; coverage of non-US products may be limited or estimated by our AI features instead.
  • RxNorm, courtesy of the U.S. National Library of Medicine (NLM), National Institutes of Health, Department of Health and Human Services. NLM is not responsible for Tavita and does not endorse or recommend it or any other product.
  • openFDA and FDA prescribing information— drug label data from the U.S. Food and Drug Administration, queried live through openFDA's public API and also used to build the on-device medicine interaction rules. openFDA data is not validated for clinical use, and its use here does not represent an endorsement by the FDA.
  • USDA FoodData Central — food and nutrient data from the U.S. Department of Agriculture.
  • Open Food Facts — packaged-food product data from the Open Food Facts collaborative database, licensed under the Open Database License (ODbL).
  • NIH Office of Dietary Supplements and NCCIH — fact sheets from the U.S. National Institutes of Health, used for nutrient guidance and for the supplement–medicine interaction rules queried on-device.
  • Anthropic Claude— powers Tavita's AI photo analysis and text-based AI features.

Purchases, backend, and hosting are handled by RevenueCat (subscriptions), Supabase (optional community backend), and Vercel (our AI proxy and this website) — each acting as a data processor for the specific feature described above.